Stored XSS Vulnerability in pfSense Plus and Community Edition
CVE-2026-56128

5.1MEDIUM

Key Information:

Vendor

Netgate

Vendor
CVE Published:
3 September 2026

What is CVE-2026-56128?

An authenticated user with permission to edit firewall schedules in pfSense Plus and Community Edition can exploit a stored XSS vulnerability. By injecting arbitrary JavaScript into the schedule description via the descr parameter in the firewall_schedule_edit.php file, the malicious payload is saved and executed in the browsers of users who access the corresponding firewall rules. This occurs due to insufficient HTML sanitization, allowing certain JavaScript code to bypass protections and lead to potential unauthorized access to sensitive data or user sessions.

Affected Version(s)

pfSense CE 0

pfSense Plus 0 < 26.07

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alex Williams from Pellera Technologies
VulnCheck
.